1 /*
2 * Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.
3 *
4 * Licensed under the Apache License 2.0 (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
8 */
9
10 #include "internal/deprecated.h"
11
12 #include <openssl/objects.h>
13 #include <openssl/core_names.h>
14 #include <openssl/evp.h>
15 #include <openssl/core.h>
16 #include "prov/securitycheck.h"
17 #include "internal/nelem.h"
18
19 /*
20 * Internal library code deals with NIDs, so we need to translate from a name.
21 * We do so using EVP_MD_is_a(), and therefore need a name to NID map.
22 */
ossl_digest_md_to_nid(const EVP_MD * md,const OSSL_ITEM * it,size_t it_len)23 int ossl_digest_md_to_nid(const EVP_MD *md, const OSSL_ITEM *it, size_t it_len)
24 {
25 size_t i;
26
27 if (md == NULL)
28 return NID_undef;
29
30 for (i = 0; i < it_len; i++)
31 if (EVP_MD_is_a(md, it[i].ptr))
32 return (int)it[i].id;
33 return NID_undef;
34 }
35
36 /*
37 * Retrieve one of the FIPS approved hash algorithms by nid.
38 * See FIPS 180-4 "Secure Hash Standard" and FIPS 202 - SHA-3.
39 */
ossl_digest_get_approved_nid(const EVP_MD * md)40 int ossl_digest_get_approved_nid(const EVP_MD *md)
41 {
42 /* TODO: FIPS 180-5 RFC 8692 RFC 8702 allow SHAKE */
43 static const OSSL_ITEM name_to_nid[] = {
44 { NID_sha1, OSSL_DIGEST_NAME_SHA1 },
45 { NID_sha224, OSSL_DIGEST_NAME_SHA2_224 },
46 { NID_sha256, OSSL_DIGEST_NAME_SHA2_256 },
47 { NID_sha384, OSSL_DIGEST_NAME_SHA2_384 },
48 { NID_sha512, OSSL_DIGEST_NAME_SHA2_512 },
49 { NID_sha512_224, OSSL_DIGEST_NAME_SHA2_512_224 },
50 { NID_sha512_256, OSSL_DIGEST_NAME_SHA2_512_256 },
51 { NID_sha3_224, OSSL_DIGEST_NAME_SHA3_224 },
52 { NID_sha3_256, OSSL_DIGEST_NAME_SHA3_256 },
53 { NID_sha3_384, OSSL_DIGEST_NAME_SHA3_384 },
54 { NID_sha3_512, OSSL_DIGEST_NAME_SHA3_512 },
55 };
56
57 return ossl_digest_md_to_nid(md, name_to_nid, OSSL_NELEM(name_to_nid));
58 }
59